<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Wololo.net &#187; 2009 &#187; October</title> <atom:link href="http://wololo.net/wagic/2009/10/feed/" rel="self" type="application/rss+xml" /><link>http://wololo.net/wagic</link> <description>Wagic, Half-Byte Loader, PSP Programming, and Homebrews</description> <lastBuildDate>Fri, 03 Feb 2012 14:17:40 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.2.1</generator> <item><title>It&#8217;s alive! Wagic 0.9.1 Released!</title><link>http://wololo.net/wagic/2009/10/29/its-alive-wagic091/</link> <comments>http://wololo.net/wagic/2009/10/29/its-alive-wagic091/#comments</comments> <pubDate>Thu, 29 Oct 2009 00:53:49 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[release]]></category> <category><![CDATA[Wagic]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=729</guid> <description><![CDATA[Cool Screenshots Finally! It feels like ages since we last did a release. I hope you waited for us and didn&#8217;t throw your PSP away in exchange for a XBox in the meantime The new version of Wagic is here, and the amount of new stuff that ships with it is simply awesome. I&#8217;m glad [...]]]></description> <content:encoded><![CDATA[<h3>Cool Screenshots</h3><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/shop.jpg"><img class="alignnone size-medium wp-image-740" title="shop" src="http://wololo.net/wagic/wp-content/uploads/2009/10/shop-300x170.jpg" alt="" width="300" height="170" /></a> <a href="http://wololo.net/wagic/wp-content/uploads/2009/10/ingame.jpg"><img class="alignnone size-medium wp-image-738" title="ingame" src="http://wololo.net/wagic/wp-content/uploads/2009/10/ingame-300x170.jpg" alt="" width="300" height="170" /></a></p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/options.jpg"><img class="alignnone size-medium wp-image-739" title="options" src="http://wololo.net/wagic/wp-content/uploads/2009/10/options-300x170.jpg" alt="" width="300" height="170" /></a> <a href="http://wololo.net/wagic/wp-content/uploads/2009/10/main.jpg"><img class="alignnone size-medium wp-image-737" title="main" src="http://wololo.net/wagic/wp-content/uploads/2009/10/main-300x170.jpg" alt="" width="300" height="170" /></a></p><p>Finally! It feels like ages since we last did a release. I hope you waited for us and didn&#8217;t throw your PSP away in <a href="http://wololo.net/wagic/2009/06/18/duels-of-the-planeswalkers-on-the-psp/">exchange for a XBox</a> in the meantime <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>The new version of Wagic is here, and the amount of new stuff that ships with it is simply awesome. I&#8217;m glad to say that some talented designers and coders recently joined our small team, dramatically improving a game that was already said to be competing with commercial software in terms of quality and replay value.</p><p>So my thanks for this release go to <em><a href="http://jhotun.com/">Jhotun</a> (art), Jeck (art and code), Psyringe (decks), Daddy32 (code)</em>, and of course the people who have been working on Wagic with me for months now: <em>abrasax, leungclj, Dr.Solomat, and J</em>.</p><p>Thanks as well to the people who provide new contents on the <a href="http://wololo.net/forum">forum</a> everyday. You can already grab extra cards in various flavors (Naruto, Final Fantasy,&#8230;), and themes to customize your experience.</p><h3>What is Wagic?</h3><p>Wagic is an heroic fantasy card game in which you battle against the computer. It is available for the Sony PSP, Windows, and Linux. In Wagic, you create a deck of cards which symbolizes your army, and fight against the AI. As you win games, you earn credits and unlock cards that you can buy in the shop. With better cards, you improve your deck (or create new ones) to beat more AI opponents and unlock other game modes. Wagic is free and open source. It is currently available in English, French, Italian, German, and Spanish.</p><h3>What&#8217;s new?</h3><p>Ok, so what&#8217;s new with this release? Well, the changes that you will most likely see at first are graphical. With the help from professional designers and developers, we got new graphics and a new user interface. Lots of customization features, as well as new cards have been added. Get ready to get some Zendikar action <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>Full changelog after the cheesy promotion video</p><p><span style='display:block;text-align:center;'><object width='450' height='365'><param name='movie' value='http://www.youtube.com/v/0LCdxkoZMnI&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' /><param name='mode' value='transparent' /><embed src='http://www.youtube.com/v/0LCdxkoZMnI&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' type='application/x-shockwave-flash' wmode='transparent' width='450' height='365' /></object></span></p><h3>Changelog</h3><ul><li>Around <strong>500 new cards</strong>. Wagic now allows you to play with <strong>more than 3500 cards out of the box</strong>. Wagic allows you to play with cards from Zendikar, Magic 2010, and 30 other expansions. This is not counting all the extra content you can get from the forum at <a href="http://wololo.net/forum">http://wololo.net/forum</a>: Naruto, Final Fantasy, and lots of other user-created sets.</li><li><strong>New shop GUI</strong>, with original graphics(see the cool screenshots above). Many thanks to Jhotun for the background image!</li><li><strong>New user interface</strong> inGame. It is highly customizable, check the options. Wagic now has some smooth animations, you&#8217;ll love the new manapool!</li><li><strong>Deck Statistics</strong> in the deck editor now show you how well your deck performs against the AI, and various useful information (average mana cost, etc&#8230;)</li><li>New <strong>Profile and Theme systems</strong> to customize your play environment. Check the Jade Theme! Also come to http://wololo.net/forum to get new themes!</li><li>Various card bug fixes</li><li>Deck Editor improved, you can now <strong>rename your decks</strong> directly in Wagic without an external text editor</li><li>Improved card graphics (Thanks J and Jeck)</li><li>Parser: <strong>new keywords</strong> (@damaged, @tapped, deathtouch, initimidate, &#8220;other&#8221; keyword for targets, &#8220;this&#8221; keyword for targets, kicker, &#8220;X&#8221; as part of abilities cost, shuffle</li><li>New <strong>caching mechanism</strong>, no need for you to setup the &#8220;size&#8221; of your cache anymore, the cache automatically uses as much Ram as possible.</li><li>New cool <strong>Game manual</strong>, check it out, it teaches you how to play Wagic!</li><li>Small <strong>AI improvements</strong></li><li>More than <strong>20 new AI Decks</strong> (Thanks Psyringe,Niegen,Abrasax and everyone who contributed)</li><li>Added an <strong>exception plugin</strong> to prevent the PSP from crashing in case of a bug. Instead, you&#8217;ll get a blue screen. (Thanks to Sakya at ps2dev)</li></ul><h3>Known issues</h3><ul><li><strong>Purple Screen of Despair:</strong> If the game has a weird purple look and feel at startup, you just got the Purple Screen of Despair. But don&#8217;t trash your PSP yet, there&#8217;s hope. We are looking for solutions to this problem, and a few techniques can be found <a href="http://wololo.net/forum/viewtopic.php?f=4&amp;t=747">here</a></li><li><strong>Blue Screen of Death:</strong> We recently added an exception handler to avoid your PSP from badly freezing. If you get a blue screen of death, it&#8217;s a bad thing because it means you found a bug in Wagic, but it&#8217;s a good thing because your PSP didn&#8217;t completely crash (so you don&#8217;t have to reboot it, and PSP3000 users know how important it is to not reboot their PSPs)</li><li>Check the <a href="http://wololo.net/wagic/bugs">list of bugs</a> before you report an issue, thanks <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></li></ul><p>Pfew&#8230; it&#8217;s always hard to summarize two months of work in a few lines&#8230; We&#8217;ve all given our best to bring you an update to one of the best homebrews out there, and we hope you&#8217;ll enjoy it.</p><h3>Thanks for your support!</h3><p>If you think this game deserves your love, please consider making a donation, it&#8217;ll help me buy a present for my wife (who deserves it for supporting me working on Wagic 24/7). Wagic has much more replay value than most &#8220;minis&#8221; available on the PSN, so think about it <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br /><center></p><form style="text-align: center;" action="https://www.paypal.com/cgi-bin/webscr" method="post"> <input name="cmd" type="hidden" value="_donations" /> <input name="business" type="hidden" value="queffelec@gmail.com" /> <input name="item_name" type="hidden" value="Wagic" /> <input name="no_shipping" type="hidden" value="0" /> <input name="no_note" type="hidden" value="1" /> <input name="currency_code" type="hidden" value="EUR" /> <input name="tax" type="hidden" value="0" /> <input name="bn" type="hidden" value="PP-DonationsBF" /> <input alt="PayPal - The safer, easier way to pay online!" name="submit" src="https://www.paypal.com/en_US/i/btn/btn_donate_LG.gif" type="image" /> <img src="https://www.paypal.com/en_US/i/scr/pixel.gif" border="0" alt="" width="1" height="1" /></form><p></center></p><p>If you want to support this game, but think homebrews and money shouldn&#8217;t be mixed, that&#8217;s perfectly fine too: please promote the game on the forums you know, create cards and themes to make the game even better, or submit bug reports. If you&#8217;re a C++ Developer, we are always looking for more good devs, so don&#8217;t be shy and join us!</p><h3>Download</h3><p>On the <a href="http://wololo.net/wagic/download">Download page</a>, as usual <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br /> The package contains the Windows, Linux and PSP versions, enjoy!</p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/29/its-alive-wagic091/feed/</wfw:commentRss> <slash:comments>16</slash:comments> </item> <item><title>My favorite Magic card is &#8220;grizzly bears&#8221;</title><link>http://wololo.net/wagic/2009/10/26/my-favorite-magic-card-is-grizzly-bears/</link> <comments>http://wololo.net/wagic/2009/10/26/my-favorite-magic-card-is-grizzly-bears/#comments</comments> <pubDate>Mon, 26 Oct 2009 13:16:57 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[magic]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=727</guid> <description><![CDATA[Yeah. That&#8217;s right, grizzly bears are my favorite. Why you ask? Well because it&#8217;s a vanilla creature. They have a power and a toughness, that&#8217;s it. Not stupid abilities that will be a nightmare to code, no fancy casting cost involving sacrifices or X or hybrid mana or saying &#8220;Beetlejuice&#8221; 3 times. No token generation, [...]]]></description> <content:encoded><![CDATA[<p><img class="alignleft" src="http://gatherer.wizards.com/Handlers/Image.ashx?multiverseid=129586&amp;type=card" alt="" width="223" height="310" />Yeah. That&#8217;s right, grizzly bears are my favorite. Why you ask? Well because it&#8217;s a vanilla creature. They have a power and a toughness, that&#8217;s it. Not stupid abilities that will be a nightmare to code, no fancy casting cost involving sacrifices or X or hybrid mana or saying &#8220;Beetlejuice&#8221; 3 times. No token generation, or triggered effect, or &#8220;choose one&#8221;, or &#8220;when it&#8217;s the first Friday of the month and if your opponent is older than you, then you deal Y damage to Z creatures where X is the sum of your age plus the color of the eyes of your opponent divided by 2&#8243;. Nope. Just a plain good vanilla creature that will never make Wagic crash <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> I love you, grizzly bears!</p><p>Seriously though, what&#8217;s your favorite card in Magic?</p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/26/my-favorite-magic-card-is-grizzly-bears/feed/</wfw:commentRss> <slash:comments>26</slash:comments> </item> <item><title>One year ago</title><link>http://wololo.net/wagic/2009/10/22/one-year-ago-2/</link> <comments>http://wololo.net/wagic/2009/10/22/one-year-ago-2/#comments</comments> <pubDate>Thu, 22 Oct 2009 04:44:24 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[Wagic]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=723</guid> <description><![CDATA[Now that this blog has been around for a little while, it&#8217;s funny for me to look at older posts. What was I talking about in October 2008? What did Wagic look like at that time? Well, unfortunately it is actually hard to see what Wagic looked like in 2008, as I was asked to [...]]]></description> <content:encoded><![CDATA[<p><img class="alignleft" src="http://gatherer.wizards.com/Handlers/Image.ashx?multiverseid=192222&amp;type=card" alt="" width="223" height="310" />Now that this blog has been around for a little while, it&#8217;s funny for me to look at older posts. What was I talking about in <a href="http://wololo.net/wagic/2008/10/">October 2008</a>? What did Wagic look like at that time?</p><p>Well, unfortunately it is actually hard to see what Wagic looked like in 2008, as I was asked to remove all pictures that contained copyrighted contents (and, at that time, there was no &#8220;picture less&#8221; mode for Wagic). But it&#8217;s still fun for me to read the old blog posts:</p><p>In October 2008, versions <a href="http://wololo.net/wagic/2008/10/09/version-010-released/">0.1.0</a> and <a href="http://wololo.net/wagic/2008/10/31/version-021-released/">0.2.1</a> were released. Version 0.1.0 introduced the test suite, and the AI became able to use a few simple spells. At that time, the game had a bit less than 500 cards. We have more than 3000 today, but I was already impressed, as my initial goal (2 years ago) was to handle around 250 cards and then stop working on the project <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> But well, Wagic has become a huge part of my life in the last 2 years (will I admit I spend 99% of my free time working on this game?), and there&#8217;s no plan to stop adding cards!</p><p>October 2008 was also the <a href="http://wololo.net/wagic/2008/10/13/no-pandora-for-psp-3000/">release date of the PSP3000</a>, and there was <a href="http://wololo.net/wagic/2008/10/17/give-me-homebrew/">no hope of hacking it</a> at that time. <a href="http://wololo.net/wagic/2009/04/15/eggsclusive-the-tiff-exploit-works-on-all-models-yes-3000-too/">Things change</a> <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>We also opened the <a href="http://wololo.net/forum">forum</a> in october 2008. For those who still don&#8217;t know, it&#8217;s a great place to get extra content for Wagic, as well as discuss future improvements to the game, and random PSP related stuff.</p><p>It&#8217;s quite fun to own a blog and be able to go back in time and read again the things I wrote a year ago <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> By the way MTGRares discusses the origins of his own program MTGForge in a <a href="http://mtgrares.blogspot.com/2009/10/mtg-forge-beginning.html">recent blog post. </a></p><p>Oh, and if you ask, we are a few weeks away from the next release of Wagic, it shouldn&#8217;t take long! (*crosses fingers*). and yes, Wagic 0.9 will have Rampaging Baloths! Actually, I believe Rampaging Baloths already works on Wagic 0.8.1, if you&#8217;re interested, check the <a href="http://wololo.net/forum/viewtopic.php?f=3&amp;t=627">Zendikar thread</a> on the forum&#8230;</p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/22/one-year-ago-2/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>Why we can&#8217;t easily find exploits in BMP images</title><link>http://wololo.net/wagic/2009/10/18/why-we-cant-easily-find-exploits-in-bmp-images/</link> <comments>http://wololo.net/wagic/2009/10/18/why-we-cant-easily-find-exploits-in-bmp-images/#comments</comments> <pubDate>Sun, 18 Oct 2009 11:24:24 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[security]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=717</guid> <description><![CDATA[Last week I gave a short introduction on how to use PSPLink for crash analysis in the XMB. Some people have been actively looking for vulnerabilities on the PSP for years now (yes, it&#8217;s a fun hobby, trust me), and crashes, as you already know, can lead to exploits (and exploits lead to homebrews, homebrews [...]]]></description> <content:encoded><![CDATA[<p>Last week I gave a short introduction on <a href="http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/">how to use PSPLink for crash analysis in the XMB</a>. Some people have been actively looking for vulnerabilities on the PSP for years now (yes, it&#8217;s a fun hobby, trust me), and crashes, as you already know, can lead to exploits (and exploits lead to homebrews, homebrews lead to anger, and&#8230;oh wait&#8230; different story).</p><p>When they don&#8217;t lead to exploits, they lead to bug fixes, which is good too, so understand this: crashing your PSP is good for Mankind.</p><p>Recently I got a BMP file from Jeerum (you can get the file on <a href="http://upsp.ws/">his forum</a>). This file crashes the PSP, and the crash looks like it could have been exploitable, except it isn&#8217;t. Rather, this example is a hint that exploiting the PSP using BMP files is probably never going to happen.</p><h3>An interesting crash</h3><p>Here&#8217;s the video. I&#8217;m running the XMB through PSPLink, and if you don&#8217;t know how to do this you should consider <a href="http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/">reading my blog more often</a> <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p><p><span style='display:block;text-align:center;'><object width='450' height='365'><param name='movie' value='http://www.youtube.com/v/EN_opA4qZzA&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' /><param name='mode' value='transparent' /><embed src='http://www.youtube.com/v/EN_opA4qZzA&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' type='application/x-shockwave-flash' wmode='transparent' width='450' height='365' /></object></span></p><p>I&#8217;m doing the usual: going to the &#8220;images&#8221; section (note that the image doesn&#8217;t crash the XMB in thumbnail mode, which is quite rare), attempt to display the image, and the PSP crashes.</p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/crash.png"><img class="size-medium wp-image-720 aligncenter" title="crash" src="http://wololo.net/wagic/wp-content/uploads/2009/10/crash-300x183.png" alt="" width="300" height="183" /></a></p><p>Now what&#8217;s interesting in this crash? Well as you see, the crash occurs when the PSP tries to Store a Word (MIPS command sw) at an address referenced by register <em>$a1 (sw $t1 8($a1) means: store the value $t1 at $a1+8)</em>. And why is it interesting you ask? Well, $a1 is equal to <strong>FF414141</strong>, and I&#8217;m quite convinced that these three &#8220;41&#8243; come from our BMP file. a value such as FF414141 doesn&#8217;t feel &#8220;natural&#8221; at all, (and that feeling is something you -quickly- get with experience). A quick look at the inside of the BMP file shows us that yes, there&#8217;s a bunch of 41&#8242;s that were put in there, and it&#8217;s quite certain that it&#8217;s where the ones we see in the crash come from.</p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/file.png"><img class="alignnone size-medium wp-image-718" title="file" src="http://wololo.net/wagic/wp-content/uploads/2009/10/file-300x218.png" alt="" width="300" height="218" /></a></p><p>Now what? Well since we can change these 41&#8242;s into what we want, it means we can write the value of t1 pretty much wherever we want in memory. It&#8217;s not an exploit yet, but it&#8217;s extremely promising.</p><h3>Not so fast&#8230;</h3><p>But wait&#8230; what&#8217;s that &#8220;FF&#8221; doing here?</p><p>Well that&#8217;s the main problem.</p><p>To really see where this FF414141 comes from, we can dump the entire contents of the PSP Ram, and check where this comes from.</p><p>To dump the Ram to a file, we type the command:</p><blockquote><p><em>savemem 0&#215;08800000 20000000000 memdump1.bin</em></p></blockquote><p>the <em>0&#215;08800000</em> is the start of what we want to dump. <em>0&#215;08800000</em> is not an address I chose randomly, it&#8217;s just the address of the beginning of the Ram. The second value is the amount of bytes we want to save. As I&#8217;m too lazy to calculate, I just enter an insanely high value to be sure all the Ram will be dumped to a file. PSPLink is clever and will stop when it reaches the end. <em>memdump1.bin</em> is the name of the file I want to save.</p><p>We can then open this file with an Hex Editor.</p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/memdump.png"><img class="size-medium wp-image-719 aligncenter" title="memdump" src="http://wololo.net/wagic/wp-content/uploads/2009/10/memdump-300x217.png" alt="" width="300" height="217" /></a></p><p>In this screenshot, the addresses I show you are random (because I already investigated this crash a few months ago and I knew what I was looking for), but in reality what you have to do, rather than randomly browsing the memdump, is to understand where the contents of $a1 come from. This is done by disassembling the code around the address of the crash, and understand (through MIPS assembly) where in Ram it read its content. To disassemble code, use the command disasm. I give a few hints on how to do that in my <a href="http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/">previous</a> <a href="http://wololo.net/wagic/2009/03/11/finding-gamesaves-exploits-on-the-psp/">articles</a>.</p><p>Ok, so the screenshot shows us a bunch of FF414141 in Ram, which is where our value came from. It&#8217;s pretty obvious they come from the 41&#8242;s we saw in the BMP. These are the contents of the BMP, reinterpreted by the PSP to display pixels on the screen, and this is what we have to deal with if we want to create an exploit.</p><p>But wait, we didn&#8217;t put thoses &#8220;FF&#8221;&#8216;s here, only &#8220;41&#8243;. So where do they come from?</p><h3>BMP files have no alpha layer</h3><p>Well to understand this you need some basics in Images on computers. Long story short, pixels on the PSP are represented with 4 bytes, ARGB (alpha, Red, Green, blue). alpha is the transparency of the pixel. Although file formats such as PNG or Tiff have an alpha layer, BMP files don&#8217;t. The PSP therefore inserts a &#8220;fake&#8221; alpha value of &#8220;FF&#8221; (which means: no transparency) for each pixel.</p><p>We&#8217;re screwed: whatever we put in the BMP file, every 4 bytes we will get a stupid &#8220;FF&#8221; inserted as a result in the PSP Ram&#8230;</p><p>Now it doesn&#8217;t mean exploits through BMP files are impossible, but it makes them difficult. Of course, the &#8220;original&#8221; series of 41&#8242;s is maybe stored somewhere else in the Ram, unchanged, but that&#8217;s unfortunately not what we deal with in this crash, which makes it useless (if we can&#8217;t control all 4 bytes of an address, we&#8217;re pretty much screwed).</p><p>I don&#8217;t think Sony planned this as a security against hackers (they have lots of other tricks against hackers, but this one is probably just the &#8220;natural&#8221; way of displaying an image with no alpha layer), but it&#8217;s still a pretty good security <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>The conclusion is that if you are looking for vulnerabilities with images on the PSP, you shouldn&#8217;t use image formats that have no transparency layer. Forget about BMPs and Gif, and try to focus on PNGs and Tiffs. <a href="http://wololo.net/wagic/2009/04/13/eggsplanations/">It worked in the pas</a>t <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/18/why-we-cant-easily-find-exploits-in-bmp-images/feed/</wfw:commentRss> <slash:comments>24</slash:comments> </item> <item><title>Looking for vulnerabilities in the PSP Firmware</title><link>http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/</link> <comments>http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/#comments</comments> <pubDate>Sat, 10 Oct 2009 04:29:04 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[psp dev]]></category> <category><![CDATA[security]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[firmware]]></category> <category><![CDATA[PSPLink]]></category> <category><![CDATA[vulnerability]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=710</guid> <description><![CDATA[I&#8217;ve described in a previous article how to look for exploits in games on the PSP. But as you may or may not know, the new PSPGo&#8217;s business model made game exploits useless for the average user. Let me explain: if an exploit is found (and revealed) in a Game on the PSP, Sony will [...]]]></description> <content:encoded><![CDATA[<p>I&#8217;ve described in a previous article <a href="http://wololo.net/wagic/2009/03/11/finding-gamesaves-exploits-on-the-psp/">how to look for exploits in games on the PSP</a>. But as you may or may not know, the new PSPGo&#8217;s business model made game exploits useless for the average user.</p><p>Let me explain: if an exploit is found (and revealed) in a Game on the PSP, Sony will simply remove the game temporarily from the PSN Store, and it will be available again only if the game&#8217;s developers fix the issue. So the only people who will be able to benefit the exploit will be those who downloaded the game from the PSN Store before the exploit was made public. (unless you didn&#8217;t know, the PSPGo has no UMD drive, and therefore all games for this machine must be bought on the PSN)</p><p>Yep, that&#8217;s not cool, and it explains <a href="http://wololo.net/wagic/2009/10/04/hello-go-psp-go-hacked/">why Freeplay doesn&#8217;t want to make the recent hack of the PSP Go public</a> (the exploit is still useful for hackers as it allows to run unsigned code on the PSPGo, and therefore analyze its firmware more precisely). It also explains why <strong>we should now be looking for vulnerabilities in the PSP Firmware (such as the laughman tiff exploit that led to chickHEN a few months ago) rather than games</strong>.</p><p>In this article I will explain how to monitor the PSP Menu with PSPLink. If you haven&#8217;t read my <a href="http://wololo.net/wagic/2009/03/11/finding-gamesaves-exploits-on-the-psp/">previous post on savegames exploits</a>, I suggest you do it, as  it is a nice introduction to PSP exploits. Disclaimer: I&#8217;m not the best PSPLink user in the world, so this article might be incomplete on some parts.</p><p><span style='display:block;text-align:center;'><object width='450' height='365'><param name='movie' value='http://www.youtube.com/v/1U56xk6ZvEo&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' /><param name='mode' value='transparent' /><embed src='http://www.youtube.com/v/1U56xk6ZvEo&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' type='application/x-shockwave-flash' wmode='transparent' width='450' height='365' /></object></span></p><h3>Setup</h3><p>Imagine you have a file that crashes your PSP. It can be a video file, an mp3, an image, etc&#8230; (I will explain later how you can find or create these files). How would you tell if it can become an exploit or not? Well, as usual, the answer is clear: PSPLink.</p><p>PSPLink is a very usueful tool to analyze the Ram of the PSP. If you don&#8217;t have it yet, google for it. I personally have the version included with the minimalist PSPSDK.</p><p>PSPLink has two parts of interest for this: one that goes on the PSP (basically, an EBOOT, as most homebrews), and two executables that run on the PC (they will display the information sent by the PSP to the PC).</p><p>Once you have installed PSPLink on your PSP and plugged your PSP to your computer with a USB cable, open 2 command-line windows, in which you will run respectively usbhostfs_pc and pspsh.</p><p>When this is done, you can run the PSPLink EBOOT on your PSP. If everything goes well, pspsh on your computer will display <em>&#8220;host0:/&#8221;</em> and usbhostfs will say <em>&#8220;Connected to Device&#8221;</em>. It should look like this:</p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/img_1025.jpg"><img class="size-medium wp-image-711 aligncenter" title="img_1025" src="http://wololo.net/wagic/wp-content/uploads/2009/10/img_1025-300x225.jpg" alt="" width="300" height="225" /></a></p><p>If you need more information on PSPLink, google for it.</p><h3>Running the XMB/VSH</h3><p>Now that&#8217;s the interesting part. If you&#8217;re a developer, you might know how to run your homebrews&#8217; prx files from there. But how can you access the PSP Menu? Well that&#8217;s actually very easy, as you only need to type the two following commands in pspsh:</p><blockquote><p><em>reset vsh</em></p><p><em>flash0:/vsh/module/vshmain.prx</em></p></blockquote><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/psplink.jpg"><img class="size-medium wp-image-712 aligncenter" title="psplink" src="http://wololo.net/wagic/wp-content/uploads/2009/10/psplink-300x111.jpg" alt="" width="300" height="111" /></a></p><p>And that&#8217;s it! Let me tell you, it is way easier than doing it for savegames, as no plugins are required.</p><h3>Test your crash</h3><p>Then what? Well, you do whatever is needed to reproduce your crash. In my case, <a href="http://wololo.net/wagic/2009/09/11/the-latest-psp-firmware-unbreakable-let-me-doubt-that/">I have an mp3 file that crashes the PSP</a>, so on my PSP I go to the music menu, and try to play the files.</p><p>When the crash occurs, pspsh should display the current state of the registers, and lots of useful information.</p><p style="text-align: center;"><a href="http://wololo.net/wagic/wp-content/uploads/2009/10/image5.jpg"><img class="size-medium wp-image-713 aligncenter" title="image5" src="http://wololo.net/wagic/wp-content/uploads/2009/10/image5-230x300.jpg" alt="" width="230" height="300" /></a></p><h3>MIPS&#8230;</h3><p>From here, what you need is MIPS assembly knowledge, and lots of patience. But I can&#8217;t teach you that <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . For the basics, you can still read <a href="http://wololo.net/wagic/2009/03/11/finding-gamesaves-exploits-on-the-psp/">my article on Savegames</a>, as we are looking for the exact same thing: a way to overwrite $ra</p><p>By the way, you need a hacked PSP to run PSPLink, so don&#8217;t try this on Official Firmwares.</p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/10/looking-for-vulnerabilities-in-the-psp-firmware/feed/</wfw:commentRss> <slash:comments>30</slash:comments> </item> <item><title>Hello Go &#8211; PSP Go Hacked</title><link>http://wololo.net/wagic/2009/10/04/hello-go-psp-go-hacked/</link> <comments>http://wololo.net/wagic/2009/10/04/hello-go-psp-go-hacked/#comments</comments> <pubDate>Sun, 04 Oct 2009 12:28:54 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=697</guid> <description><![CDATA[Congrats to Freeplay, and whoever else is behind the exploit (I&#8217;m suspecting it&#8217;s MaTiaZ, from the &#8220;everyone who deserves it&#8230;&#8221; line) So the PSP Go got hacked, but Freeplay mentions he will not release the exploit. It makes sense, as the game will be removed/patched from the PSN as soon as the exploit is made [...]]]></description> <content:encoded><![CDATA[<p>Congrats to Freeplay, and whoever else is behind the exploit (I&#8217;m suspecting it&#8217;s MaTiaZ, from the &#8220;everyone who deserves it&#8230;&#8221; line)</p><p><span style='display:block;text-align:center;'><object width='450' height='365'><param name='movie' value='http://www.youtube.com/v/wTDh3Kye5fY&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' /><param name='mode' value='transparent' /><embed src='http://www.youtube.com/v/wTDh3Kye5fY&amp;border=0&amp;rel=0&amp;egm=0&amp;color1=0x666666&amp;color2=0xefefef' type='application/x-shockwave-flash' wmode='transparent' width='450' height='365' /></object></span></p><p>So the PSP Go got hacked, but Freeplay mentions he will not release the exploit. It makes sense, as the game will be removed/patched from the PSN as soon as the exploit is made public, making the exploit useless. Just use this for hope <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>By the way, this means <a href="http://wololo.net/wagic/2009/06/10/the-psp-go-already-hacked/"> I was right</a> from the start <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p><p>Edit: The google ads make me laugh, suggesting &#8220;anti hackers&#8221; websites when I post stuff about PSP hacking <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/04/hello-go-psp-go-hacked/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> <item><title>Win a PSP GO!</title><link>http://wololo.net/wagic/2009/10/02/win-a-psp-go/</link> <comments>http://wololo.net/wagic/2009/10/02/win-a-psp-go/#comments</comments> <pubDate>Fri, 02 Oct 2009 04:30:26 +0000</pubDate> <dc:creator>wololo</dc:creator> <category><![CDATA[Uncategorized]]></category><guid isPermaLink="false">http://wololo.net/wagic/?p=695</guid> <description><![CDATA[PSPGen launched a contest today to win a psp go. The concept is to follow their website and answer 10 questions that will be asked in the next 2 weeks. Rules of the contest are in French, so I guess non French speakers will not be interested, but the more the merrier Once you win [...]]]></description> <content:encoded><![CDATA[<p>PSPGen launched a contest today to win a psp go. The concept is to follow their website and answer 10 questions that will be asked in the next 2 weeks.</p><p>Rules of the contest are in French, so I guess non French speakers will not be interested, but the more the merrier <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p><p>Once you win it, don&#8217;t forget to send it to me <img src='http://wololo.net/wagic/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p><p><a href="http://www.pspgen.com/concours-gagnez-psp-go-avec-pspgen-jour-1-actualite-190069.html">source</a></p> ]]></content:encoded> <wfw:commentRss>http://wololo.net/wagic/2009/10/02/win-a-psp-go/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 21/56 queries in 0.287 seconds using disk: basic

Served from: wololo.net @ 2012-02-04 14:33:36 -->
